Rigcheck

Guides

How to set up SPF, DKIM and DMARC for Google Workspace

Google Workspace handles your email, but it doesn't automatically publish all the records that prove that email is really yours. Unless you bought your domain through Google when you signed up, you'll usually need to set up at least DKIM yourself, and often SPF and DMARC too.

Without them, your messages are more likely to land in spam, and Gmail, Yahoo and Microsoft require all three from anyone sending email in volume. Setup takes about 15 minutes of work, plus some waiting for DNS.

See what's already in place. Rigcheck detects Google Workspace and shows which of the three records you're missing.

Check your domain

Before you start

  • Google Workspace admin access, to generate the DKIM key.
  • Access to your DNS host, wherever your domain's DNS records are managed (Cloudflare, GoDaddy, Namecheap, Route 53 and so on). This isn't always where you bought the domain. Rigcheck shows your DNS host at the top of your results.

Step 1: SPF

SPF lists the servers allowed to send email for your domain. For Google Workspace, add this TXT record at the root of your domain (the name is usually @):

v=spf1 include:_spf.google.com ~all

If you already have an SPF record, don't add a second one. A domain can only have one, and two records cause SPF to fail completely. Instead, add include:_spf.google.com to your existing record, before the ~all at the end. For example, if you also send newsletters through Mailchimp:

v=spf1 include:_spf.google.com include:servers.mcsv.net ~all

If your record is getting long, read SPF too many DNS lookups. Each include uses part of a limited budget.

Step 2: DKIM

DKIM adds a digital signature to every message, which receivers check against a public key in your DNS. It's the most important of the three, because it survives forwarding and it's what most often makes DMARC pass. Google generates the key for you.

Generate the key in Google

  1. In the Google Admin console, go to Menu → Apps → Google Workspace → Gmail.
  2. Click Authenticate email.
  3. In the Selected domain menu, choose your domain.
  4. Click Generate new record. Choose a 2048-bit key unless your DNS host can't handle long records, and leave the prefix (selector) as google.
  5. Click Generate. Google shows a DNS host name (like google._domainkey) and a long TXT record value starting with v=DKIM1.

Add it to your DNS

At your DNS host, create a TXT record:

FieldValue
TypeTXT
Namegoogle._domainkey
ValueThe full v=DKIM1; k=rsa; p=... value from Google

Enter just google._domainkey in the name field. Most DNS hosts add your domain automatically, and typing the full name can produce google._domainkey.yourdomain.com.yourdomain.com, which silently fails. Copy the value in one piece. Missing even one character breaks the key.

Turn on signing

Back on the Authenticate email page, click Start authentication. This step is easy to miss: publishing the record alone doesn't make Google sign your mail.

If Google says it can't find the record, wait and try again. New DNS records can take a while to appear, and the Admin console may keep showing a reminder to update your DNS records for up to 48 hours.

Step 3: DMARC

DMARC tells receivers what to do with mail that fails SPF and DKIM, and sends you reports about who's sending as your domain. Add a TXT record named _dmarc:

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

Replace the address with an inbox you'll check. Start with p=none so nothing gets blocked while you confirm everything passes, then tighten it over the following weeks. DMARC p=none vs quarantine vs reject walks through that rollout.

Step 4: Confirm it works

  1. Run your domain through Rigcheck. SPF should pass, DKIM should show a key for the google selector, and DMARC should be in place.
  2. Send a message from your Workspace account to a personal Gmail address. Open it, tap the three-dot menu and choose Show original. You should see PASS next to SPF, DKIM and DMARC.

Common problems

  • DKIM shows as missing. Usually the record name has the domain doubled, the value was cut off when copying, or Start authentication was never clicked.
  • "Record too long." Some older DNS hosts can't store a 2048-bit key in one record. Most split it into chunks automatically. If yours doesn't, generate a 1024-bit key instead.
  • SPF fails after adding Google. Check for a second SPF record left behind by a previous email provider, and remove it.
  • Mail from other tools still fails. These records only cover mail sent through Gmail. Your website's contact form, CRM, help desk and newsletter tool each need their own authentication set up in their settings.

Sending app email through Google Workspace

A common shortcut is to send your app's or website's email (password resets, receipts, notifications) through a Workspace mailbox using SMTP. It works at first, but it has real downsides:

  • Sending limits. Google caps how many messages each user account can send per day. Go over, and that account can be blocked from sending for a period, including the person whose mailbox it is.
  • Shared reputation. A surge of automated mail or spam complaints affects the same account your team uses for everyday email.
  • No visibility. You won't get delivery logs, bounce handling or the analytics you need to debug "I never got the reset email."

The more reliable setup is a dedicated transactional email service, sending from a subdomain like mail.yourdomain.com with its own SPF and DKIM. Your team's mailboxes and your app's email then can't affect each other. We're putting together an independent comparison of transactional email providers to help you choose.

Check your Google Workspace setup. See which records pass and get the exact fix for anything missing.

Check your domain

More guides